AZ-500 Manage identity and access Practice Question
A company needs to demonstrate compliance with the Payment Card Industry Data Security Standard (PCI DSS) for their Azure workloads. They use Microsoft Defender for Cloud for security management. Which feature should they use to view their current compliance status against PCI DSS controls and track progress over time?
⚠ Common exam trap
Test-takers frequently confuse the Recommendations blade (which shows individual security findings) with the Regulatory compliance dashboard (which aggregates those findings into a compliance framework view), leading them to select Recommendations instead of the correct dashboard.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regulatory compliance dashboard
The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of compliance posture against standards like PCI DSS. It maps Azure resource configurations to specific PCI DSS controls, shows pass/fail status per control, and tracks compliance score over time, enabling continuous monitoring and evidence collection for auditors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security policy
Why it's wrong here
Security policy in Microsoft Defender for Cloud is an implementation of Azure Policy initiatives that define configuration rules for resources, such as requiring encryption or restricting network access. The Security policy blade lets you enable and monitor policy assignments, but it reports compliance only at the level of policy definitions and resource types, not as a mapped view of PCI DSS requirement families. It does not aggregate policy failures into a regulation-specific compliance score or display per-requirement pass/fail status, so it is not the dashboard used to demonstrate PCI DSS compliance.
- ✗
Recommendations
Why it's wrong here
Recommendations surface discrete, prioritized security findings—for example, a SQL database should have vulnerability assessment enabled or an NSG should restrict a port—along with the affected resource and an optional remediation step. Although each recommendation can be linked to the underlying regulatory assessments, the Recommendations view does not organize those findings by PCI DSS requirements or tell you which controls have overall passed or failed. It also lacks the framework-level summary and manual 'customer responsibility' actions that the Regulatory compliance dashboard provides, so it cannot by itself prove statutory compliance.
- ✓
Regulatory compliance dashboard
Why this is correct
The Regulatory compliance dashboard continuously evaluates selected standards, including PCI DSS 3.2.1, through built-in Azure Policy initiatives and displays the overall percentage of compliant controls across your subscriptions. It maps each standard requirement to compliance controls, shows the resources that passed or failed the linked policies, and identifies which failed recommendations must be fixed to restore that control. You can also drill down to view evidence, assign manual assessments for customer-managed controls, and track compliance trends over time, making it the correct place to demonstrate PCI DSS status.
- ✗
Security incidents
Why it's wrong here
Security incidents are aggregated groups of alerts that correlate related attack indicators, such as a suspicious sign-in followed by lateral movement, and are designed for threat response in Defender for Cloud. They focus on active or historical intrusions, associated entities, and investigation paths, but they do not map to PCI DSS control families or regulatory requirements. Because incident triage does not evaluate policy or configuration state against a compliance framework, it cannot produce a compliance score or evidence set for a payment-card audit.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.